Patents Assigned to CROWDSTRIKE, INC.
-
Patent number: 12689642Abstract: A system and method of using generative AI to identify exposures of computing devices on computing networks to actual and/or potential threats. The method includes collecting a plurality of responses from a plurality of devices to a target device on a private network. The method includes providing the plurality of responses to a classification model trained to assign device descriptions for device responses based on semantic matching of the device responses to database data. The method includes assigning, by the processing device using the classification model, a plurality of device descriptions for the plurality of responses to the target device, each response is respectively associated with one or more device descriptions of the plurality of device descriptions. The method includes generating, based on the plurality of device descriptions, a status report comprising a list of network addresses associated with a group of devices having access to the target device.Type: GrantFiled: November 29, 2023Date of Patent: July 21, 2026Assignee: CrowdStrike, Inc.Inventors: Paul Sumedrea, Damian Monea
-
Patent number: 12688281Abstract: The present disclosure provides techniques for AI model-based detection explainability. A processing device obtains computer-readable text and an indication of a false positive detection of malicious behavior with respect to the computer-readable text by a cybersecurity system, The processing device obtains, via an artificial intelligence (AI) model trained to generate language, a reason for the false positive detection of the malicious behavior. The processing device provides an indication of the reason for the false positive detection to a destination device.Type: GrantFiled: May 30, 2024Date of Patent: July 21, 2026Assignee: CrowdStrike, Inc.Inventors: Diana Bolocan, Mihaela-Petruta Gaman
-
Publication number: 20260205476Abstract: IT asset discovery services and external attack surface management (or EASM) services identify computers, servers, smartphones, and other devices that are exposed to the public Internet. Any device that can connect to the public Internet may be vulnerable to cybersecurity attacks. The services identify a device exposed to the public Internet by generating an asset inventory discovery graph. Graphical nodes describe asset inventory investigative records, and edges between the graphical nodes describe asset inventory investigative methods. The nodes thus capture asset investigatory details (such as website URL, IP addresses, and HTML content), and the edges capture how the asset investigatory details were discovered (such as Internet searches, DNS records, and WHOIS records). The services use the asset inventory discovery graph to identify an entity's Internet-facing assets.Type: ApplicationFiled: January 13, 2025Publication date: July 16, 2026Applicant: CrowdStrike, Inc.Inventors: Michael Brian Goldgeier, Yaron Tal, Moshe Shimon Perez, Michael Glyer, Yotam Lichter
-
Patent number: 12682057Abstract: A cloud-based file integrity monitoring service identifies content changes to a computer file. An endpoint cybersecurity agent monitors its host client device for read/write and other operating system events associated with the computer file. When the endpoint cybersecurity agent detects each operating system event, the endpoint cybersecurity agent captures and reports, in real time or near real time, a snapshot of the file content representing the computer file. So, as the host client device changes the computer file with each operating system event, the endpoint cybersecurity agent uploads timestamped snapshots of the file content to a cloud-based file integrity monitoring service. The cloud-based file integrity monitoring service stores each snapshot of the file content, thus logging a change history for the computer file.Type: GrantFiled: May 30, 2024Date of Patent: July 14, 2026Assignee: CrowdStrike, Inc.Inventors: Silviu-Alexandru Badragan, Andrei-Viorel Cotiga, Adam Freund, Samantha Alyn Goresh, Ioan Tinca
-
Patent number: 12676833Abstract: A firewall receives a flow of data from a first computing resource destined to a second computing resource and searches, in a memory, a prefix tree data structure, the prefix data structure comprising a linked plurality of nodes corresponding to normalized criteria for each of a plurality of rules, for any rule in the plurality of rules that applies to controlling the received flow of data between the first computing resource and the second computing resource. If the search is successful, a set of rules in the prefix tree data structure is identified that apply to controlling the received flow of data from the first computing resource to the second computing resource in response to the searching. One of those rules in the set is then selected to control the received flow of data from the first computing resource to the second computing resource.Type: GrantFiled: January 28, 2022Date of Patent: July 7, 2026Assignee: Crowdstrike, Inc.Inventors: Keehun Nam, Tim Adams
-
Patent number: 12675570Abstract: Methods and systems implement computing systems configured to trigger a volatile memory scan based on execution of computer-executable instructions, and to downselect scope of a volatile memory scan. Such techniques for triggering scans are sufficiently selective to avoid volatile memory scans for each and every running process, or vast majority of running processes. Moreover, volatile memory scans are triggered responsively after the computer-executable instructions are run, so that target processes to be scanned have not yet terminated at the time of the volatile memory scan. Additionally, a variety of techniques are implemented to minimize the volatile memory scans adversely impacting computational performance of the computing system.Type: GrantFiled: August 11, 2023Date of Patent: July 7, 2026Assignee: CrowdStrike, Inc.Inventors: Jennifer Mankin, Blair Foster, Marc Leclair, Eric Kuhl
-
Publication number: 20260178829Abstract: An LLM log parsing service parses log data using at least one large language model. The LLM log parsing service, however, may evaluate multiple log parser candidates. Each log parser candidate parses a sample of the log data using the at least one large language model. The LLM log parsing service generates a log parser decision that selects which one of the log parser candidates best performs as a log parser. The LLM log parsing service then parses the log data using the best log parser.Type: ApplicationFiled: December 20, 2024Publication date: June 25, 2026Applicant: CrowdStrike, Inc.Inventors: James Robert Plush, Sean Berry
-
Patent number: 12665921Abstract: Techniques for calculating risk scores of entity assignments are discussed herein. The system generates a probability matrix using a collaborative filtering technique such as singular value decomposition. The probability matrix is populated with probability values for each entity representing a probability that, based on the various relationships or associations of that entity with other entities, the entity has been granted an assignment. Risk values are used to provide a weighting value to assignments, separating relatively higher risk assignments from relatively lower risk assignments. The system thereafter calculates a risk score for one or more of the entities using the information in the assignment matrix, the probability matrix, and the risk values. The system can flag or identity one or more entities whose risk scores do not meet various criteria.Type: GrantFiled: November 28, 2023Date of Patent: June 23, 2026Assignee: CrowdStrike, Inc.Inventors: Robert Molony, Michael Brautbar, Manu Nandan, Ciaran O'Brien
-
Publication number: 20260170133Abstract: A cybersecurity model assessment service assesses machine learning and/or artificial intelligence models for cybersecurity threats. The cybersecurity model assessment service may particularly assess a pickle file associated with an AI/ML model. A dynamic emulation reveals whether the pickle file represents normal or abnormal computer behavior. The dynamic emulation of the pickle file may thus reveal whether the AI/ML model is safe or unsafe to use.Type: ApplicationFiled: December 16, 2024Publication date: June 18, 2026Applicant: CrowdStrike, Inc.Inventors: Stefan Cicos, Alexandru-Constantin Ghita, Andrei Stoian, Paul-Danut Urian
-
Publication number: 20260172451Abstract: An endpoint cybersecurity reinforcement learning agent uses reinforcement learning to implement cybersecurity actions. The endpoint cybersecurity RL agent interfaces with a host operating system as an antimalware driver. The endpoint cybersecurity RL agent receives an event notification generated by the OS and determines a responsive cybersecurity action using the reinforcement learning. The endpoint cybersecurity RL agent implements the cybersecurity action via the OS. The endpoint cybersecurity RL agent thus greatly improves computer functioning by quickly learning to identify new/novel suspicious events and operations.Type: ApplicationFiled: December 16, 2024Publication date: June 18, 2026Applicant: CrowdStrike, Inc.Inventors: Arnd Korn, Ian Torres
-
Patent number: 12659228Abstract: A system and method of using generative AI to recommend and validate asset and/or cloud configurations. The method includes acquiring a set of parameters associated with one or more network entities of a computing network. The method includes providing the set of parameters to a configuration model trained to generate, based on semantic matching, recommended configurations for network entities and validated configurations for the network entities. The method includes generating, by a processing device using the configuration model, one or more recommended configurations for the one or more network entities based on the set of parameters.Type: GrantFiled: January 5, 2024Date of Patent: June 16, 2026Assignee: CrowdStrike, Inc.Inventors: Paul Sumedrea, Damian Monea
-
Patent number: 12651057Abstract: A deterministic finite automata (DFA) is used by an extended Berkley packet filter (or “eBPF”) to monitor file system operations and non-file system operations. The DFA is stored as an eBPF map. Before a kernel of an operating system executes any file system operation, the kernel runs an eBPF program that queries the DFA for a filename associated with the system operation. The DFA represents safe/suspicious filenames associated with computer files. If the filename matches the DFA, then the kernel notifies a cybersecurity agent. The cybersecurity agent may then block or allow the file system operation, depending on whether the filename is safe or suspicious. The DFA stored in the extended BPF thus greatly improves computer functioning by very quickly and simply identifying safe/suspicious operations.Type: GrantFiled: October 26, 2023Date of Patent: June 9, 2026Assignee: CrowdStrike, Inc.Inventor: Justin John Kevin Deschamp
-
Patent number: 12645796Abstract: The present disclosure provides an approach of analyzing multiple modalities of a file to produce multiple analysis tokens. Each one of the analysis tokens corresponds to a respective modality of the file. The approach provides the multiple analysis tokens to an artificial intelligence model, which is trained to produce an intermediate representation vector based on the plurality of analysis tokens. In turn the approach uses the artificial intelligence model to produce, based on the intermediate representation vector, a classification that indicates whether the file corresponds to a cybersecurity threat.Type: GrantFiled: January 25, 2024Date of Patent: June 2, 2026Assignee: CrowdStrike, Inc.Inventors: Andrew Southgate, Paul Sumedrea
-
Patent number: 12632624Abstract: The present disclosure provides techniques for sensor event based activity hour modelling. A processing device obtains, via a sensor application installed on a user device, a plurality of events occurring on the user device, where each event in the plurality of events includes a respective day and a respective time. The processing device aggregates, based on the respective day and the respective time, the plurality of events to generate time series data. The processing device performs a smoothing operation on the time series data to generate a curve. The processing device classifies an event on the user device as usual or unusual based on a baseline level of activity on the user device and the curve.Type: GrantFiled: January 21, 2025Date of Patent: May 19, 2026Assignee: CrowdStrike, Inc.Inventors: Tim Rütermann-Franz, Cullen Boldt, Ori Zuckerman
-
Patent number: 12634299Abstract: Techniques for aggregating data usable for generating security recommendations are discussed herein. A system can aggregate detection data from host devices associated with different organizations based on profile information describing each organization. The system can analyze the aggregated data to identify potential security threats in a data stream, and generate recommendation data usable for defending the data stream from future malicious events.Type: GrantFiled: May 30, 2023Date of Patent: May 19, 2026Assignee: CrowdStrike, Inc.Inventors: Theo Chihaia, Jaclyn Abrams, Joel Robert Spurlock, Joseph Faulhaber
-
Patent number: 12627700Abstract: Techniques, systems, and computer-readable media for dynamic behavior-based asset classification are described herein. An asset classification system can detect and receive data associated with a host computer, determine, based on the data, a behavior associated with the host computer, assign the host computer a server classification based on the determination that the behavior represents a behavior of focus, and record the assigned server classification associated with the host computer. In various examples, the asset classification system can determine the behavior is a behavior of focus based on one or more of: a number of connections to other computers associated with a shared customer identifier, a number of unique other host computers connecting to the host computer, and/or a number of unique non-local accounts that have logged in to the host computer, and that the host computer has had an inbound connection on a common port.Type: GrantFiled: December 19, 2023Date of Patent: May 12, 2026Assignee: CrowdStrike, Inc.Inventors: Ryan Inghilterra, Shaefer Drew, Michael Brautbar
-
Patent number: 12625973Abstract: Prediction of CPEs using banners greatly improves computer functioning. Many web services have an unknown common platform enumeration (CPE). When the CPE is unknown, a computer system is unable to obtain cybersecurity flaws and software fixes for a software product or web service. A CPE, though, is predicted by banner-prompting a large language model using a web service banner. Once the CPE is predicted, vulnerabilities may be identified.Type: GrantFiled: February 10, 2025Date of Patent: May 12, 2026Assignee: CrowdStrike, Inc.Inventors: Shaefer Drew, Michael Avraham Brautbar
-
Patent number: 12627692Abstract: Malicious indicators rule generation using historical data is provided. A method includes receiving, from threat detection engines of a plurality of vendor systems, a plurality of threat detection indications for a dataset. Each threat detection indication of the plurality of threat detection indications receives a vendor-specific tokenization based on historical data associated with the plurality of vendor systems. The method further includes identifying, from the plurality of threat detection indications, a lead detection from a first vendor system of the plurality of vendor systems and an accuracy detection from at least one second vendor system of the plurality of vendor systems. The lead detection and the accuracy detection have overlapping data from the dataset.Type: GrantFiled: May 6, 2024Date of Patent: May 12, 2026Assignee: CrowdStrike, Inc.Inventors: Mihai Maganu, Andrei Stoian, Ernest Szocs, Paul Urian
-
Publication number: 20260127265Abstract: A cybersecurity model assessment service assesses machine learning and/or artificial intelligence models for cybersecurity threats. When an endpoint client device encounters an ML/AI model, the client device may stop processing the ML/AI model and determine its provenance. The provenance identifies a base, foundational, or origin model from which the ML/AI model derives. The provenance, for example, determines whether the ML/AI model originates from, derives from, or is sufficiently similar to a known good/safe model or to a known bad/unsafe model. The cybersecurity model assessment service may then predict a computer behavior of the ML/AI model, based on the provenance. Similarity to a known good/safe model, for example, may be safe to run, while similarity to a known bad/unsafe model is unsafe to run.Type: ApplicationFiled: November 1, 2024Publication date: May 7, 2026Applicant: CrowdStrike, Inc.Inventors: Andrew Southgate, Alexandru Dinu, Dragos Georgian Corlãtescu, Ioana Croitoru
-
Patent number: 12619429Abstract: Systems and methods of utilizing a large language model (LLM) to reverse engineer software is provided. The method includes obtaining sample assembly language from coded information or data. The sample assembly language is input to a machine learning (ML) model trained to recognize when the sample assembly language includes malicious code. The method further includes identifying, from the sample assembly language, a functionality implemented by the sample assembly language, where the functionality is indicative of whether the sample assembly language includes the malicious code. The method further includes generating, by a processing device, a natural language indication of the functionality implemented by the sample assembly language. The natural language indication is an output of the ML model.Type: GrantFiled: December 26, 2023Date of Patent: May 5, 2026Assignee: CrowdStrike, Inc.Inventors: Felix Schwyzer, Aditya Kapoor, Calin-Bogdan Miron, Marian Radu